CVE-2024-22329: IBM WebSphere Application Server
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.3 are vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker could exploit this vulnerability to conduct the SSRF attack. X-Force ID: 279951.
Affected products
- IBM WebSphere Application Server: from 8.5.0.0, before 8.5.5.26 (fixed in 8.5.5.26); from 9.0.0.0, before 9.0.5.20 (fixed in 9.0.5.20); from 17.0.0.3, before 24.0.0.4 (fixed in 24.0.0.4)
Published 2024-04-17. Last modified 2026-06-17.